Last Notes
I thoroughly read all of the technical documentation on Coldcard before I bought one. I was convinced that Coinkite had gone above and beyond in every aspect. I was confident that my generated key was safe and secure. I remote signed transactions and imported them to Sparrow with an SD card. I thought I was my own most secure bank. It's pure luck that this attack didn't happen sooner before I decided to cash out a whole coin at 100k. If I hadn't swept that wallet and ditched the device I would have been reading about the theft of my own funds on social media like happened to several others. All of us whether affected or not have learned a valuable lesson in the past 24 hours.
#nevent1q…aeuf
Technically buff-tailed/white-tailed - most likely workers from the Bombus terrestris–lucorum group.
The fact that every other wallet manufacturer is coming out saying seeds generated with their products aren’t at risk of this vulnerability suggests it was entirely preventable, and that is why it is right for people to direct their anger at Coinkite here.
Well their docs claimed truthfully that the device is equipped with a hardware tRNG module, but nobody realized that the code was fucked and this hardware wasn't being utilized.
Attention? Not having much accountability also means people do what they normally wouldn’t.
disagree, their job was to generate seeds. why else would you have a hardware wallet that's airgapped?
Be careful not to discount or minimize the real suffering people are experiencing as a result of this incident. “Kindness” and “grace” do not negate the need for accountability where accountability is warranted. This represents for some a loss of their entire life savings. If it was the result of negligence or carelessness by the defacto hardware wallet manufacturer, as it appears it was from initial information, then their pain is real and their anger is justified.
Maybe it would be beneficial to have a series of blog posts demystifying hardware wallets and Bitcoin security.
For privacy. If you put all your UTXOs in one address then you risk revealing your entire balance with one non-private transaction. It's better to have one UTXO per address. Without your private or public key nobody looking at the blockchain knows those addresses are linked by your keys. This way you can spend from one UTXO without revealing ownership of the others. For the same reason you should always use new and separate change addresses.
This one's making the rounds and I'm here for it
#nevent1q…9ddv
I 100% agree, but don't forget that the mocking happened in both directions. And humans are humans.
When you tell someone to put in the work they are going to resist and they are often going to be very mean about it, and they are often going to rub it in your face for as long as all the things that you tell them could go wrong, never goes wrong.
Finally, we have a real world story that we can use to get people to take us seriously. This one hit hard. We will get better. Sometimes things need to happen before things can get better.
Vasectomies are not 100% effective.
Turns out this is safer than generating a seed with Coldcard 👇🤣
https://www.bitaddress.org/bitaddress.org-v3.3.0-SHA256-dec17c07685e1870960903d8f58090475b25af946fe95a734f88408cef4aa194.html
Yes, but that tells you nothing about the seed. You cannot crack one seed individually but have to sweep over all possible seeds.
At which point, you will have found all the targets anyway indiscriminately
boating accident is so 2017.
It did not affect self custody, it affected halfway-house self custody.
This is the only way we can learn unfortunately. It's super sad, super unfortunate, very stressful and pretty disastrous. But those who told you how to avoid this type of situation we're being ignored and maybe even laughed at Probably more laughed at by the people who just kept their shit on exchanges but, still.
I think I've become a physical entropy maxi now
Most normal people prefer to outsource security anyway. That's why banks exist. Self custody is for control-freak weirdos only. Always will be.
I'm zooming in on the 40MB RAW file, I can see their hairs have split ends.
They need good shampoo 😂
This whole thing completely sank the self-custody ship.
#nevent1q…tqvt
Normal people aren’t going to roll a dice. They’re just going to store their bitcoin on exchange from this point forward.
No one can be sure it will not happen..
Posted a note about this more than a year ago.. ii was already smelling this kind of FUD
https://media1.tenor.com/m/_90ngLQufGIAAAAC/sheeeeiiittt.gif
Over 1K now
https://npub1lrnvvs6z78s9yjqxxr38uyqkmn34lsaxznnqgd877j4z2qej3j5s09qnw5.blossom.band/e98967c09af4a65e1831b0f7ecf0012d5ff68eb0297fee380cce8fbfabce2239.jpg
I call this one:
"3 bees on a sunflower":
https://i.nostr.build/aB7fM5VM4sNxwFiE.jpg
https://media1.tenor.com/m/G9lyfGiunzIAAAAC/tea-spill-the-tea.gif
https://media1.tenor.com/m/LLu6EdwJk3sAAAAC/big-oof-size.gif
Nah, I think it is the opposite to all of our shortcuts and attempts to put security second to convenience.
Cryptography is sound and the source entropy was always its achilles heel. Cyprography always advertised that it is only ever as good as the entropy you give it.
High concentration gives you a similar risk level, regardless of the asset. It's unreasonable to expect normal users to become cryptographers. Better to expect them to diversify wallets. Best to diversify wallets _and_ assets.
And invest in the people around you. Surround yourself with people who would continue to care about you, even if you were broke. They remain your best insurance against all risk and **we have no idea what man-made horrors are fast approaching us**. This was just the warning shot.
A very late GM
If I'm boring you with bee shots, do let me know 😂
#Photography
https://i.nostr.build/iu4Zwc7PcEH5pygr.jpg
https://npub1832epq8kgur55cuwnnrdf3y85p4l4wqsgq42hxn8jna5ngznz5lq2law2l.blossom.band/5926a0d01d0a7a7e3049874046e70a79af8d69ba1b4a2659d23b50f2d4cff4ce.mp4
#nevent1q…nmce
Over 1K BTC now
https://npub1lrnvvs6z78s9yjqxxr38uyqkmn34lsaxznnqgd877j4z2qej3j5s09qnw5.blossom.band/e98967c09af4a65e1831b0f7ecf0012d5ff68eb0297fee380cce8fbfabce2239.jpg
On a positive note: you don't have to charter a yacht for that boating accident to be plausible now.
I was satisfied with the way their docs bragged about using hardware tRNG and two separate secure element chips but it turns out the hardware tRNG wasn't even being utilized. This is very bad and the only reason I'm not a victim of this attack is pure luck that it didn't happen before I moved my funds end of 2024. This RNG fallback flaw is something that should have been caught in review and never made it to production. The fact that they didn't even know that their devices were doing this is a deathblow to this company's reputation.
always love some good news, especially on days when all the news seems bad!
congrats!
I saw some of your stack was swept. Sorry to hear it brother.
Yes the shilled 'gold standard' of single sig self custody being exploited really is a devestating hit for self custody.
July 31st
YOUR CAREER IS NOT A LIFE SENTENCE
“How disgraceful is the lawyer whose dying breath passes while at court, at an advanced age, pleading for unknown litigants and still seeking the approval of ignorant spectators.”
—SENECA, ON THE BREVITY OF LIFE, 20.2
#DailyStoic
Nah, Blocktron is way cooler.
What about OpenDimes…are they safe?
Nah, they know what it will be worth.
Hard not to roll your eyes at all the pictures like this that have been posted over the years. They didn’t need to break into homes, take people hostage, threaten anyone with violence. They did it much more efficiently and quietly, right out from under everyone’s noses. There was absolutely no defense against that. https://onlydans.blossom.band/f93fabfc061020fa8d3d56eb295f66f8e0c3ea651e870ef1c1e11673d70b622a.png
I was taken in by the Coldcard sales pitch. Operated on the assumption that my funds were as secure as they could be by remote signing with my CC and broadcasting with Sparrow on my own node. The only reason why I'm not a victim of this attack is pure luck that it didn't happen sooner. When Bitcoin hit 100k, I decided to start cashing out a whole coin and moved my CC funds to a hot wallet and started selling a million sats per day.